Privacy Policy
Last updated: July 15, 2026
1. Who we are
Lone Tree Ventures LLC, a California limited liability company, doing business as PermitPipeline ("PermitPipeline," "we," "us," or "our"), is the operator of this Service. For privacy questions or requests, email [email protected] or write to 490 Post St Ste 500 PMB 2054, San Francisco, CA 94102.
2. What we collect
When you sign up or use the Service, we collect:
- Account info: your email address, name, and (if you subscribe) the company you represent.
- Payment and fraud-prevention info: Payments are processed by Stripe. From Stripe we may receive confirmation of payment, your card brand, the last four digits, billing country, and fraud or risk signals. We do not receive or store your full card number. We use this information to process payments and to prevent fraud and abuse.
- Usage data: which lead emails you open, what you click, what filters you apply in the dashboard. Standard web analytics.
- Device and security info: IP address, user agent, browser and device type, session identifiers, sign-up and cancellation timestamps, referrer and campaign (UTM) parameters, information you provide if we place your account under manual review (such as business or license details), and our fraud and security decisions. We use this to secure accounts, prevent abuse, and operate the Service.
- Communications: emails or support messages you send us.
- Private beta requests (if applicable): if you request invite-only beta access, we may collect your name, email, company, phone number, city/market, trade or role, and website. We use this information to review fit, provide access, send product emails, and improve the service.
- Feature usage details: which projects you save, notes and stages you enter in Project Tracking, which Contact Finder lookups you request and the party those lookups return, saved searches and filters you configure, your CSV or data exports, your Daily Project Brief preferences, and, for Team accounts, which team member performed each action. We use this to bill lookups, run the product, support your team, and improve scoring.
3. How we use it
- To deliver the Service (send the daily digest, maintain your account, process payments).
- To improve scoring and product based on what subscribers actually open and click.
- To send you account-related emails (billing receipts, renewal notices, product updates).
- To respond to your questions and support requests.
- To secure the Service and prevent fraud and abuse.
4. What we don't do
- We do not sell or share your subscriber account information or website-usage information for cross-context behavioral advertising.
- We do not share your email with advertisers or lead buyers.
- We do not contact property owners on your behalf.
- We do not disclose your account or usage information to unrelated PermitPipeline customers. Within a Team account, saved searches, saved projects, notes, pipeline stages, and activity created by any member are visible to the account owner and other members of that Team, and remain with the Team account if a member leaves. Account owners have administrative visibility into their Team's workspace for billing, management, and continuity.
5. Third parties we work with
We use a small number of tools to run the Service. Each has its own privacy policy.
- Stripe — payment processing.
- Resend — email delivery.
- Cloudflare — hosting and DNS.
- Google Analytics 4 — usage analytics. GA4 uses first-party cookies (
_ga,_ga_4EH2C6WGJH), device and browser information, and site activity to measure visits and conversions. Google states that GA4 does not log or store individual IP addresses, though IP addresses are processed transiently for location and security. We do not send names, emails, or other direct identifiers to Google Analytics, and we do not use it for advertising personalization. - Contact-data and identity-enrichment providers — sources for Contact Finder and record matching. They receive only the query information needed to return a result.
- Fraud-prevention and payment-risk services (via Stripe) — used to detect duplicate or abusive sign-ups.
- Public city building-department records — the source of the project information we use to provide the Service, including NYC Open Data, Chicago Data Portal, San Francisco DBI, and Miami-Dade Regulatory and Economic Resources. Public records may be incomplete, delayed, revised, or subject to source-specific terms.
We only share with these providers what they need to do their job.
5.5. Information about people named in project records
PermitPipeline's core service is project intelligence built from public records. Separately from subscriber data, we process information about individuals and businesses named in construction and property records — for example property owners, architects, engineers, contractors, permit applicants, filing representatives, and business principals, including parties returned through our Contact Finder feature.
- What we process: name; business role or professional license; business or mailing address; permit or filing relationship; phone number and email where available; project and company associations; and likely-match or confidence indicators.
- Where it comes from: city building-department records, county assessor records, professional-license records, and other public sources, together with licensed third-party contact-data and enrichment providers.
- How we use it: to build project records, identify project participants, provide Contact Finder results, de-duplicate and match records, and improve our scoring and project intelligence.
- Who receives it: authorized PermitPipeline subscribers.
This information may be incomplete, out of date, or incorrectly matched. If you believe information we display about you is wrong, misidentified, or should not be shown, email [email protected] and we will review it. We can correct or suppress information within PermitPipeline; we cannot change the underlying government record, and we may retain records where required for legal, security, or public-record reasons.
6. How long we keep your data
We keep different information for different periods:
- Account and profile information — while your account is active, and up to 12 months after cancellation.
- Team workspace content — kept under the Team account until the account owner deletes it or the Team account closes.
- Billing and tax records — as long as required by law and standard accounting practice.
- Fraud and security records — for a defined security-retention period.
- Support communications — for a defined support and legal period.
- Purchased Contact Finder credits and their records — while associated with your account.
- Public project and contact records — while reasonably needed to provide the Service, subject to the correction and suppression process in Section 5.5.
- Backups — deleted on a rolling schedule.
Canceling stops future renewal and access at period end; it does not automatically delete your account or all retained records. You can request deletion of eligible information by emailing [email protected].
7. Your rights
Depending on where you live, you may have rights to:
- Know what personal data we hold about you.
- Request a copy of it.
- Ask us to correct or delete it.
- Opt out of marketing emails (every email has an unsubscribe link).
Email us at [email protected] to exercise any of these rights.
You can opt out of marketing emails at any time. Billing, security, and legally required account notices cannot be opted out of while your account is active. Daily Project Brief and product alerts can be managed separately in Settings. Unsubscribing from marketing does not cancel a paid subscription.
7.5. Your California Privacy Rights
If you are a California resident and PermitPipeline is a business covered by the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) with respect to your information, you have the rights below. In addition, whether or not that law applies, we will make reasonable efforts to honor verified requests to access, correct, or delete your account information, subject to legal, security, public-record, billing, and Team-account exceptions.
- Right to know what personal information we collect, use, and disclose.
- Right to delete personal information we have collected from you.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information (we do not sell or share subscriber account information for cross-context behavioral advertising).
- Right to limit use of sensitive personal information (we do not intend to collect sensitive personal information).
- Right to non-discrimination for exercising these rights — we will not deny service, charge a different price, or provide a different quality of service.
To make a request, email [email protected] with the subject line "California Privacy Request." We verify your identity before acting, accept authorized-agent requests with proof of authorization, and will tell you if we cannot honor a request and why. We will respond within 45 days. We will not discriminate against you for exercising these rights.
We do not intend to collect sensitive personal information. Please do not enter Social Security numbers, financial-account credentials, health information, or other highly sensitive personal information into project notes or other free-text fields.
8. Security
We maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information, including encrypted transport (HTTPS), access controls, and trusted payment processors. No system is completely secure. If a security incident triggers a legal notification obligation, we will provide notice as required by applicable law.
9. Cookies
We use a small number of cookies for basic site functionality and analytics:
- Google Analytics 4 sets first-party cookies (
_ga,_ga_4EH2C6WGJH) to measure page views, signups, and conversions. These expire within 2 years. - Session cookies for logged-in users (dashboard, account settings).
We do not run advertising pixels or remarketing trackers on this site. You can block cookies in your browser, or opt out of Google Analytics via the Google Analytics Opt-out Browser Add-on, without losing core functionality.
Do Not Track and opt-out signals. Browsers may send "Do Not Track" signals, but there is no uniform industry standard for them, and we do not currently respond to legacy DNT signals. Where applicable law requires, we will honor recognized opt-out preference signals such as Global Privacy Control (GPC) for activity that constitutes a sale or sharing of personal information. We currently do not use subscriber information for cross-context behavioral advertising. If that changes, we will update this policy before activating any such tracker.
10. Children
The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children under 13 (consistent with the Children's Online Privacy Protection Act). If you believe we have, contact us and we'll delete it.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll notify subscribers by email. The "Last updated" date at the top always reflects the current version.
12. Contact
Questions about privacy? Email [email protected].